Bit Locker can now be installed before the Operating system is deployed unlike previous OS versions where Bit Locker was provisioned post installation.

Administrator can choose if entire volume needs to be encrypted or only used space, unlike previous OS versions that encrypt entire volume including free space.

New Network Unlock feature that doesn’t prompt you to enter TPM+PIN in a domain environment by automatically unlocking the Operating System at system reboot provided system is connected to a trusted wired corporate network. It is generally useful while installing software patches in unattended fashion to desktops and servers.